Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2023-22816 CVE-2023-22815 |
CWE-ID | CWE-77 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
My Cloud PR2100 Hardware solutions / Other hardware appliances My Cloud PR4100 Hardware solutions / Other hardware appliances My Cloud EX4100 Hardware solutions / Other hardware appliances My Cloud EX2 Ultra Hardware solutions / Other hardware appliances My Cloud Mirror G2 Hardware solutions / Other hardware appliances My Cloud DL2100 Hardware solutions / Other hardware appliances My Cloud DL4100 Hardware solutions / Other hardware appliances My Cloud EX2100 Hardware solutions / Other hardware appliances WD Cloud Hardware solutions / Other hardware appliances My Cloud Hardware solutions / Office equipment, IP-phones, print servers My Cloud OS 5 Operating systems & Components / Operating system |
Vendor | Western Digital |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU77683
Risk: Medium
CVSSv4.0: 5.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-22816
CWE-ID:
CWE-77 - Command injection
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation in a CGI file. A remote user can pass specially crafted data to the application and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsMy Cloud PR2100: All versions
My Cloud PR4100: All versions
My Cloud EX4100: All versions
My Cloud EX2 Ultra: All versions
My Cloud Mirror G2: All versions
My Cloud DL2100: All versions
My Cloud DL4100: All versions
My Cloud EX2100: All versions
My Cloud: All versions
WD Cloud: All versions
My Cloud OS 5: before 5.26.300
CPE2.3https://www.westerndigital.com/support/product-security/wdc-23010-my-cloud-firmware-version-5-26-300
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU77685
Risk: Low
CVSSv4.0: 5.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-22815
CWE-ID:
CWE-77 - Command injection
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation in a CGI file. A remote administrator can pass specially crafted data to the application and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsMy Cloud PR2100: All versions
My Cloud PR4100: All versions
My Cloud EX4100: All versions
My Cloud EX2 Ultra: All versions
My Cloud Mirror G2: All versions
My Cloud DL2100: All versions
My Cloud DL4100: All versions
My Cloud EX2100: All versions
My Cloud: All versions
WD Cloud: All versions
My Cloud OS 5: before 5.26.300
CPE2.3https://www.westerndigital.com/support/product-security/wdc-23010-my-cloud-firmware-version-5-26-300
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.